CVE-2013-4783
Last modified
CVE-2013-4783 is a vulnerability of currently unknown severity. The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are intended to be on a separate management network; they are not designed nor intended to be placed on or connected to the Internet.". EPSS estimates a 3.38% chance of exploitation in the next 30 days.
Description
The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password. NOTE: the vendor disputes the significance of this issue, stating "DRAC's are intended to be on a separate management network; they are not designed nor intended to be placed on or connected to the Internet."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Idrac6 Bmc | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4783?
How severe is CVE-2013-4783?
How do I fix CVE-2013-4783?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4777A certain configuration of Android 2.3.7 on the Motorola Def…
- CVE-2013-4778core/getLog.php on the Siemens Enterprise OpenScape Branch a…
- CVE-2013-4779Cross-site scripting (XSS) vulnerability in core/handleTw.ph…
- CVE-2013-4780core/getLog.php on the Siemens Enterprise OpenScape Branch a…
- CVE-2013-4781core/getLog.php on the Siemens Enterprise OpenScape Branch a…
- CVE-2013-4782The Supermicro BMC implementation allows remote attackers to…
- CVE-2013-4784The HP Integrated Lights-Out (iLO) BMC implementation allows…
- CVE-2013-4785The web interface on the Dell iDRAC6 with firmware before 1.…
- CVE-2013-4786The IPMI 2.0 specification supports RMCP+ Authenticated Key-…
- CVE-2013-4787Android 1.6 Donut through 4.2 Jelly Bean does not properly c…
- CVE-2013-4788The PTR_MANGLE implementation in the GNU C Library (aka glib…
- CVE-2013-4789SQL injection vulnerability in modules/rss/rss.php in Cotont…
Are you affected by CVE-2013-4783?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
